Firefox Add-ons

Macondo Utils

by Hridya Agrawal · 13 users
b4be66c7-bd40-56d1-97e0-0a98db69f506 | v0.9.0
58/ 100
MEDIUM risk
No change since v0.8.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (58/100) still counts them.

Analysis record

Analysed
2 months ago
Version
v0.9.0
Artifact
SHA256 242…A9C
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

11 detail rows

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

94 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Hridya Agrawal

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

48
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
12
Portfolio

12 evidence rows available.

Finding Categories

10
Network
94
IoC Indicators

Requested Permissions

4 permissions
tabs
Medium
storage
Low
https://macondo.hackclub.com/*
Low
https://macondoutils.hridya.tech/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Macondo Utils is a Firefox extension described as providing "quality-of-life improvements for Macondo, including better estimates, project labels, streak details, and goals tracking." The security findings are dominated by known false positive patterns rather than evidence of actual malicious behavior.

The most alarming statistic—166 IoC findings—is characteristic of the XIOC extractor's documented noise patterns. Of these 166 findings, only three specific domains are identified: 8.tj, 3.by, and w.tj (from findings titled XIOC-DOMAIN-8.tj, XIOC-DOMAIN-3.by, and XIOC-DOMAIN-w.tz). The remaining 163 IoC findings are almost certainly garbage artifacts: IPv6 fragments, property access chains misread as domains, or CDN infrastructure domains. This extraction noise is a well-documented issue with the tool and does not indicate malicious activity.

The nine network findings (NET-FETCH-content.js-1631, NET-FETCH-content.js-3664, NET-FETCH-content.js-3627, NET-FETCH-content.js-5383, NET-FETCH-content.js-1639, NET-FETCH-content.js-1623, NET-FETCH-content.js-3599, NET-FETCH-content.js-1615) are generic fetch call detections. These findings identify that content.js makes HTTP requests but do not reveal suspicious destinations. Any extension that communicates with a backend service will trigger these rules.

Critically, the findings show zero malware signatures and zero obfuscation findings. These are the actual indicators of malicious code. The absence of malware signatures means no known malicious patterns matched the extension's code. The absence of obfuscation means the code is readable and not attempting to hide its behavior.

The manifest analysis finding (MANIFEST-SENSITIVE-PERM-TABS in manifest.json) flags the tabs permission as potentially sensitive. This is a standard permission that legitimate productivity extensions require to read and modify webpage content. It is not inherently malicious.

Addressing the strongest counterargument: Critics might point to the anonymous developer (empty developer_name field) and unusual domains as evidence of risk. While the anonymous publisher is a legitimate concern, it alone does not indicate malicious intent. The three specific domains (8.tj, 3.by, w.tj) are unusual but cannot be confirmed as malicious without additional threat intelligence. More importantly, if this were a malicious extension, we would expect to see malware signatures, obfuscation, credential theft indicators, or typosquatting—none of which are present. The 166 IoC findings are a false alarm from a noisy detection system, not evidence of malicious behavior.

The extension's coherent description, lack of malware signatures, and absence of obfuscation strongly suggest this is a legitimate utility extension flagged by detection noise.

Key Reasons

  • Zero malware signatures detected in the extension code
  • Zero obfuscation findings—code is readable and not hiding behavior
  • 166 IoC findings are characteristic of XIOC extractor noise, not actual malicious domains
  • Network findings are generic fetch calls without suspicious destination evidence
  • Extension has coherent description matching legitimate productivity utility purpose

False Positive Considerations

  • XIOC extractor garbage (166 findings with only 3 specific domains)
  • Generic network fetch detection rules
  • Common manifest permission (tabs) flagged as sensitive

Reviewed 2026-06-03; recommended action: suppress false positive; model confidence 75%.

Firefox version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
58
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
0.4.0
Jun 2, 2026
Risk range
58 to 59
Across analyzed versions
Latest analyzed version
0.9.0
Jul 8, 2026
Selected version
medium
Version
v0.9.0
2 months ago
Risk score
58
Findings
105
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Macondo Utils adds practical upgrades to the Macondo experience so important information is easier to see and use. Features: - Personalized shop time estimates based on your actual project pace - Ground labels on farm tiles with useful project metadata - In-page streak details without leaving the dashboard - Goals HUD with progress tracking and quick controls - Lightweight onboarding and “what’s new” walkthroughs for new versions

Frequently Asked Questions